Who changed this med order on Tuesday? From which device? Answered.
Every state-changing action writes to the audit log — userId, IP, user-agent, and a non-PHI after-blob describing what changed. Immutable. Admin-viewable. Filterable by user, action, and date.
When a state auditor or your own QIDP asks "who changed this med order on Tuesday from which device," you answer in one query, not a multi-day forensic exercise.
Destructive admin actions are mirrored to a separate ops bucket — even if someone with admin access tries to cover tracks, the parallel record survives.